Reasons to care about Viacom v. Google - Zd Net Asia.com: Last Thursday's 200-page dump of cour... http://bit.ly/crqRzF #SME #UMG #WMG #EMI
1 hour 3637 seconds ago by metaphysicalist on topsyZDNet is available in the following editions:
Lately, security conferences have been bad news for SSL. At this year's Black Hat, independent security guru Moxie Marlinspike explained how he was able to completely bypass SSL security.
http, marlinspike, michael kassner, moxie marlinspike, sha-1, ssl, sslstrip, web browser, web page, web server
In January I wrote an article, SSL: Really broken this time, in which I described how forged certificates could be created if the signing Certificate Authority used the MD5 algorithm for signing.
That wasn't too difficult of a problem to rectify; it just required Certificate Authorities to use SHA-1 instead of MD5. Even so, most people in the know realized that it won't be too long before SHA-1 has the same problem as MD5.
SSLsniff
Well, I'm afraid that cracking SHA-1 is the least of our problems.
You may remember Moxie Marlinspike, he's the developer of a sophisticated hacking tool called SSLsniff. The application exploits vulnerabilities in Internet Explorer, allowing Man-in-the-Middle (MitM) attacks even if SSL connections are used. Microsoft eventually fixed the vulnerabilities by disallowing leaf certificates to act as signing certificates.
Even with the vulnerability fixed, SSLsniff is still a powerful tool. As evidence, SSLsniff was used to demonstrate MitM attacks by the group of cryptographers who discovered the MD5 exploit I mentioned earlier.
SSLstrip
Marlinspike's new and improved tool is called SSLstrip. Quite simply, SSLstrip allows an ill-intended attacker to capture sensitive personal information without even worrying about encryption.
He decided to sidestep the encryption process once he realized that users almost always request Web pages using the http (unencrypted) prefix. That's even the case for the more confidential Web sites like those provided by financial institutions as shown below:
After the initial portal page is brought up, https is enabled after some user intervention as the following image shows:
SSLstrip is simply a MitM proxy that advantages this flaw/oversight in the https process by stepping in between the user and in this case the bank's Web server. Let's look at the process using me as the guinea pig:
Something is wrong though, how come the "s" is missing from http in the URL? I thought the bank's Web site was secure. It's not there because the SSL connection was setup between my attackers' computer and the bank's Web server. I was getting all the correct Web pages sent to my computer, but not over secure channels. Guess who now has my log in credentials?
I realize that an observant user would more than likely be aware of the sleight of hand taking place here, but then I suspect that many more will be fooled by this. For more details about the exploit, please view Marlinspike's Black Hat presentation New Tricks for Defeating SSL in Practice (pdf). He did a great job explaining the entire process.
Even sneakier
In Marlinspike's presentation, he points out a few other techniques that can be applied to make the unsecure Web page look more convincing. Most Web browsers display the favicon supplied by the Web server right next to the URL in the address bar. What SSLstrip allows you to do is replace the favicon with one of your choosing.
By doing this many more people will be fooled as they have been told to look for a closed lock and if it's there then they can be assured that they are safe.
It's even possible for the attacker to supply a real SSL connection to the requesting computer with a URL that's almost identical to the one asked for. The difference being a few extra characters at the end. Moxie Marlinspike explains in the next slide:
Change the Web browser
We humans are creatures of habit; I doubt that anyone would argue that. Knowing that, I honestly can't say that I'd catch the deception every time myself. One good thing is that this dilemma has been talked about by others. I was fortunate that TechRepublic's managing editor Jason Hiner alerted me to George Ou's article HTTPS Web hijacking goes from theory to practice.
The article explains that developers need to give Web browsers enough intelligence to know whether the connection should be SSL encrypted or not and if encryption isn't occurring to disallow the connection. George also mentions that Google is working on this very problem in their early versions of the Chrome 2.o Web browser. Hopefully other Web browser developers will follow suit.
Final thoughts
First, I'd like to thank Black Hat for the use of their logo and Marlinspike for the use of his presentation slides in this article. I also admire his wanting to make everyone aware of this potentially serious attack vector.
I realize that this exploit is one that requires inattentiveness on our part. Fortunately, most people I talk to mention that they wouldn't get caught by this. Just to test that theory, think back to the last time you went to a Web site that used SSL. Did you check the URL? Were you sure that the traffic was encrypted? I didn't.
Michael Kassner has been involved with IT for over 30 years, and is currently a systems administrator for an international corporation and security consultant with MKassner Net.
Reasons to care about Viacom v. Google - Zd Net Asia.com: Last Thursday's 200-page dump of cour... http://bit.ly/crqRzF #SME #UMG #WMG #EMI
1 hour 3637 seconds ago by metaphysicalist on topsyit depend of his culture the modern ones yes , but the old fashion no , if he like you for not serious relationship , the he just need a ...
1 hour 58 minutes ago by collingridge on Philippine antipiracy drive focuses on enterprisesit depend of his culture the modern ones yes , but the old fashion no , if he like you for not serious relationship , the he just need a ...
1 hour 58 minutes ago by collingridge on Philippine antipiracy drive focuses on enterprisesi would look into technical colleges around ur area to see if they offer that program. most technical schools offer it.
Joliese Tan
@BarackObama People voted you in for change. Why are you not listening on ACTA http://tinyurl.com/y8u56g9 #hcr HCR
2 hours 11 minutes ago by studio1411 on topsyMB Kabbalah IChing - Free Software Downloads - ZDNet Asia: MB Kabbalah IChing is a zodiac sign based software that... http://bit.ly/czUQRr
3 hours 5 minutes ago by fighting_jew on topsyAs Sony camera users, both MTS and M2TS are Sony high definition video file types, which are raw AVCHD videos recorded by AVCHD camcorder...
3 hours 47 minutes ago by tracyjump on Mobile data centers becoming 'mainstream'Found this great little deal calculator http://www.zdnetasia.com/downloa...
10 hours 26 minutes ago by winstoncranford on topsyRead my blog post on getting the most from your Nexus One: http://www.zdnetasia.com/blogs/m...
16 hours 43 minutes ago by mistertechblog on twitterRT @3wconsulting: Whitepaper from http://3W.com.au "Outsourcing Your IT Requirements to Philippines" now on @zdnetaustralia & @zdnetasia http://ow.ly/1oY9f
1 day 57 minutes ago by LeesaAT3W on twitterWhitepaper from http://3W.com.au "Outsourcing Your IT Requirements to Philippines" now on @zdnetaustralia & @zdnetasia http://ow.ly/1oYbA
1 day 58 minutes ago by itemployment on twitterWhitepaper from http://3W.com.au "Outsourcing Your IT Requirements to Philippines" now on @zdnetaustralia & @zdnetasia http://ow.ly/1oYbz
1 day 58 minutes ago by brucemills on twitterZdnetasia.com Estimated Worth $178,365 USD. Daily Ad Revenue:$244 USD, Daily Views:81,445 Pages... - http://www.haplog.com/www.zdneta...
1 day 41 minutes ago by Haplog on twitterThe receivers don't transmit back to the satellite. Unless there is a phone line attached to the receiver, they don't have any wa...
2 days 23 minutes ago by bessellbrowne on Apple to join the geolocation craze?whatever little understanding I have we 'll only progress toward end of the world if we use HPCs to lenthen life of human being. Huma...
2 days 30 minutes ago by abhi32002@gmail.com on High computing promises elixir of lifeThanks for the knowledgeable article on SDDs. Allas...when all this reasearch will happen in Indian Universities. Hope the new bill on Fo...
2 days 42 minutes ago by abhi32002@gmail.com on APAC HPC users eye solid-state drivesIt was a good article. This brings a good opportunity for Indian IT firms to come up with new solutions in this field. HPC can become a b...
2 days 1 minute ago by abhi32002@gmail.com on High computing most-wanted job in AsiaCOL KR DHARMADHIKARY(RETD) its very late to reply the link, but if it is still alive and looking for opportunity, i would like to know th...
2 days 58 minutes ago by deb021280 on Education takes off in rural India, helped by PCsHigh performance computing (HPC) most-wanted job in Asia http://bit.ly/9vFC3i (via @zdnetasia) #singapore
2 days 15 minutes ago by mySingapore on twitterRT @zdnetasia: EMC COO, Pat Gelsinger, on bridging gaps in the organization and its cloud ambitions in Asia. (cont) http://tl.gd/i5jjd
2 days 4 minutes ago by mistymaitimoe on twitterEMC COO, Pat Gelsinger, on bridging gaps in the organization and its cloud ambitions in Asia. http://bit.ly/9etOZW
2 days 8 minutes ago by zdnetasia on twitterAsian SMBs need to pay more attention to disaster recovery planning http://bit.ly/bDet08 via @zdnetasia
2 days 23 minutes ago by asiapacsolution on twitterAsian SMBs need to pay more attention to disaster recovery planning http://bit.ly/bDet08
2 days 38 minutes ago by zdnetasia on twitter"YOG should have social media rules, too - Internet - News" http://bit.ly/dn6vjD
2 days 46 minutes ago by socialsentiment on topsy[TECH] URL Shorteners slow Web redirection. - http://bit.ly/bySnWK @zdnetasia
3 days 21 minutes ago by danielcktan on twitterURL shorteners are great but they can slow web redirection & you pray it would never go down http://bit.ly/bySnWK via @zdnetasia
3 days 49 minutes ago by angahsin on twitterURL shorteners slow Web redirection. http://bit.ly/bySnWK
3 days 18 minutes ago by zdnetasia on twitterChinese agencies cry foul over Google. http://bit.ly/by6rwV
3 days 24 minutes ago by zdnetasia on twitterall of sg's isps have been practising compulsory invisible proxy for all home subscribers at their backend since many years back alre...
3 days 42 minutes ago by melvinchia on Web filters mean bad news for businessit is not to good for china.
Proactol
Very good explanation of JMX
4 days 32 minutes ago by Babith B on Managing applications with JMXThe reaction to a report issued Tuesday by Flurry Analytics managed to completely overlook some interesting news--the Android-based Motorola Droid outsold the original iPhone over the same period of time following their respective launches--to focus instead on the sales numbers for the Nexus One.
5 days 36 minutes ago by lonemavericks on diggsAnother ZTE story....
5 days 38 minutes ago by Moderate Your Greed on Philippines opens bid for final 3G licenseWe at www.fifosys.com have also seen a growth in IT outsourcing and anticipate it as a growing field.
5 days 11 minutes ago by sarah Jane on Companies' outsourcing spend to increaseI agree with you. The iSiVaL is super portable and TVs can't expand their image size. I recorded a video that might bring some ideas to...
5 days 41 minutes ago by Jesse B Andersen on Buying a projector? Try an LED TV insteadThe Desktop Virtualization Revolution is here!
Find our more with Citrix Simplicity is Power
2010 IT Salary & Skills Report
Find out the salary range of IT professionals. Join activeTechPros for free access to the report.
The Internet Show 2010, 21-22 Apr 2010, Singapore
FREE admission for visitors who pre-register online. Register Today!